What to do after you’ve gained root access

  1. Disable auditing
  2. Grab password file
  3. Create and “adminkit”
  4. Enumerate server information
  5. Enumerate secrets of LSA
  6. Dump Registry info
  7. Use Nltest
  8. Pilfer the box
  9. Add an administrator account
  10. Grab a remote command shell
  11. Hijack the GUI
  12. Disable Passprop
  13. Install a back door
  14. Install Trojan horses and sniffers
  15. Repeat
  16. Hid the adminkit
  17. Enable auditing